Cybersecurity

ASOS Confirms Breach After Hackers Hijack App Push Notifications
Cybersecurity
ASOS Confirms Breach After Hackers Hijack App Push Notifications
ASOS confirmed a breach after attackers sent a fake push alert claiming a Snowflake hack; names and contact details may be exposed, but not card ...
Application Security
Ninja Forms, WPC Product Bundles XSS Flaws Used to Backdoor Sites
Attackers are exploiting stored XSS flaws in Ninja Forms and WPC Product Bundles to install a fake plugin with four persistence mechanisms on WordPress.
CVE Vulnerability Alerts
Pwn2Own Ireland 2026 Day One: 32 Zero-Days, $388,500 in Payouts
Researchers demonstrated 32 unique zero-day exploits on day one of Pwn2Own Ireland 2026, earning $388,500 against phones, routers, printers and AI platforms.
Application Security
Attackers Scan for Rejetto HFS Session-Forgery Flaw CVE-2026-61500
Scanning has begun for CVE-2026-61500 in Rejetto HFS, a flaw that lets attackers forge admin cookies and reach remote code execution on versions 3.0.0-3.2.0.
CVE Vulnerability Alerts
Dell Patches Root-Level Flaw CVE-2026-86360 in System Update Tool
Dell fixed a critical path traversal, CVE-2026-86360, in its System Update CLI that lets unauthenticated remote attackers run code as root, plus four more bugs.
CVE Vulnerability Alerts
Android October 2026 Update Patches 25 Flaws, Seven Rated Critical
Google's Android security bulletin for patch level 2026-10-01 fixes 25 vulnerabilities, seven of them critical, with no in-the-wild exploitation reported.
Application Security
LibreOffice, OpenOffice Flaws Run Code From Spreadsheets Silently
CVE-2026-63277 in LibreOffice and CVE-2026-59265 in Apache OpenOffice let malicious spreadsheets run code through JDBC drivers with no macro warning shown.
Cybersecurity
Gentlemen Ransomware Affiliate Used MCP as Command Channel
CloudSEK found Gentlemen RaaS affiliate Azazel using Model Context Protocol as a command channel in live intrusions that hit 24-plus victims in six countries.
Cybersecurity
UIC College of Medicine Hit by Booba Ransomware, 344 GB Claimed
The University of Illinois Chicago says data was taken from College of Medicine servers; the Booba ransomware gang claims 344 GB stolen from the school.
Cybersecurity
Denmark CPR Breach Exposes Data of 8.8 Million People
Attackers abused a private firm's lawful lookup rights to pull names, addresses and CPR numbers of 8.8 million people from Denmark's Central Person Register.